dhi.io/k8ssandra-operator
1.31-debian-fips, 1.31-debian13-fips, 1.31-fips, 1.31.0-debian-fips, 1.31.0-debian13-fips, 1.31.0-fips
sha256:4583f4e4ff98bd1150c0ca7762433675f2c7afeeb912f013694f17a9f8697dd4
Manifest digest:sha256:faebc87acb953e219b7fcb10e5403fe7a9c77cceb5fdbda41cc163c4313d82ea
Size
21.86 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/k8ssandra-operator:1.31-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/k8ssandra-operator:1.31-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/k8ssandra-operator@sha256:243b8af214cd9d32b8486faeb7895e8a6cf1a6f3704990f6fac7c6f2565d0bdd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/k8ssandra-operator@sha256:0de9dbdf89db77100afedc6e60d0ee4fb00cc0957fbd22eb7484f9a25f043c75 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/k8ssandra-operator@sha256:34ed7cafc44f382a766a857377364fef581574ccbfcbf9d2e16ff6cb18003950 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/k8ssandra-operator@sha256:1317221fde360a5ef2fa4d3e8b420368f99f0e8e75b51c503680e9cfba333735 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/k8ssandra-operator@sha256:370702cfaab7a2c6975400283f0c25dc78b4dc3b616cefc4eccbe1d514fbe4e9 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/k8ssandra-operator@sha256:31776cb4c28e097ed4abc53e2a248601c488d80f1488de5e59eba340431c6462 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/k8ssandra-operator@sha256:192601f52792a2ace7a5e8ae2f644e686c9364ce9a6025416d7e51f76c105392 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/k8ssandra-operator@sha256:49b0840cfa89e7f03d592dbbf137d0c4a029eba23ac78c417c8affa2f39b8068 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/k8ssandra-operator@sha256:758de6ba6ad734ae92afefaf4da61d86b03e3e3486848c0f8585933c6c63ea78 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/k8ssandra-operator@sha256:717111e3afeaebb8b73a8980ea09137410f89ce8401c4b9bb6bde18ac595b282 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/k8ssandra-operator@sha256:8f6e45ebd3c1cf9bca103b586bd3ee4dbeec5f92384753440e2507a86669a458 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/k8ssandra-operator@sha256:4255c1f927a9910e203d4dbc486fb7f10941d3b670300905277d231b0c5b0b25 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/k8ssandra-operator@sha256:857fc0523bc5042f9ad9d92104938317d8ebb7ae8c0cbf0fd1b991d760ed1aaa |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/k8ssandra-operator@sha256:4bf9551f3ff96f51b0b959a7e6a174f77f134323a3092ab5ab42805cf849447c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/k8ssandra-operator@sha256:3741b7ed250ad44e2fe19c1b8d70f58bde11de6195e99316e313d054afbad0cb |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/k8ssandra-operator@sha256:9e51953b3a25abf176d7e4423c888866c640b6893e62bbee77ba048e42dfd314 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/k8ssandra-operator@sha256:171134612c8cb440fb7d8528d7b989fca68a5b1d619748184e573e4c2acf3ef2 |